Security & Vulnerability Disclosure
Machine-readable version: /.well-known/security.txt (RFC 9116).
Reporting a vulnerability
Email support@rafanest.com with a description of the issue, the steps to reproduce it, and any proof-of-concept material. We read every report and will acknowledge yours within 5 business days.
Scope
rafanest.com and its subdomains (including practitioner sites at <clinic>.rafanest.com), and our public API. Our mobile apps (RafaNest on iOS and Android) are in scope for issues in the app itself, not for issues in the App Store or Play Store platforms.
Out of scope
Denial-of-service or load testing, spam or social engineering against our staff or customers, physical access attempts, and automated scanning aggressive enough to degrade service for real users. Findings that require a compromised device or browser extension to exploit are also out of scope.
Handling patient data
RafaNest is a healthcare platform under HIPAA. Do not attempt to access, modify, download, or exfiltrate real patient data at any point during testing — create your own test account (or email us for one) and confine any proof-of-concept to accounts and data you control. A report built on accessing real patient records will not be eligible for safe harbor below.
Safe harbor
We will not pursue legal action against a good-faith researcher who follows this policy: stays within scope, avoids the data-handling line above, and reports privately to us before any public disclosure. Give us 90 days to investigate and remediate before disclosing publicly.
Recognition
This program does not currently pay bounties. With your permission, we’ll credit you by name here once a report is fixed. We’re evaluating a paid program as the company grows.